Back
CVE-2003-0616
Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
Published: Aug 27, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| mcafee | epolicy_orchestrator | 2.0 |
| mcafee | epolicy_orchestrator | 2.5 |
| mcafee | epolicy_orchestrator | 2.5 |
| mcafee | epolicy_orchestrator | 2.5.1 |
GitHub Security Advisory GHSA-3vcr-m67m-mr3p
Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1...
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
3.04%
Top 14% most likely to be exploited
Threat Score
30.9 / 100
Data Sources
NVD
EPSS
GitHub